or
Sign in to turn on 1-Click ordering.
 
 
Express Checkout with PayPhrase
What's this? | Create PayPhrase
More Buying Choices
38 used & new from $5.27

Have one to sell? Sell yours here
 
   
SQL Server Security
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get your Kindle here.
 
  

SQL Server Security (Paperback)

~ David Litchfield (Author) "In the early days of personal computing, security was often an afterthought, if it was never thought of at all..." (more)
Key Phrases: obfuscated password, multiserver administration, fixed server roles, Enterprise Manager, Active Directory, Server Agent (more...)
4.8 out of 5 stars  See all reviews (4 customer reviews)

List Price: $49.99
Price: $32.99 & this item ships for FREE with Super Saver Shipping. Details
You Save: $17.00 (34%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
Upgrade this book for $4.99 more, and you can read, search, and annotate every page online. See details
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Only 5 left in stock--order soon (more on the way).

Want it delivered Tuesday, November 24? Choose One-Day Shipping at checkout. Details
22 new from $12.22 16 used from $5.27

Frequently Bought Together

SQL Server Security + The Database Hacker's Handbook: Defending Database Servers + Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase
Price For All Three: $118.07

Show availability and shipping details


Customers Who Bought This Item Also Bought

The Database Hacker's Handbook: Defending Database Servers

The Database Hacker's Handbook: Defending Database Servers

by David Litchfield
4.9 out of 5 stars (7)  $31.50
Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase

Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase

by Ron Ben-Natan
4.9 out of 5 stars (11)  $53.58
The Oracle Hacker's Handbook: Hacking and Defending Oracle

The Oracle Hacker's Handbook: Hacking and Defending Oracle

by David Litchfield
4.5 out of 5 stars (6)  $32.84
The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws

The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws

by Marcus Pinto
4.9 out of 5 stars (15)  $31.50
SQL Server Security Distilled, Second Edition

SQL Server Security Distilled, Second Edition

by Morris Lewis
4.7 out of 5 stars (7)  $40.45
Explore similar items

Editorial Reviews

Product Description

Addresses SQL Server vulnerabilities and provides security solutions. Covers installation, administration, and programming--plus security issues such as authentication, encryption, intrusion detection, and more. Written for IT professionals administering or programming any SQL Server-based application--includes coverage of SQL Server 7, SQL Server 2000, and SQL Server (Yukon).


From the Back Cover

Protect your data from the most sophisticated hackers with hands-on examples and sure-fire measures in SQL Server Security. Understand the ways in which SQL Server can be hacked, and what you can do to prevent exploitation of your data. Install, administer, and program secure Microsoft SQL Server environments and applications. Assess your risk and threat levels when designing a secure system. Make sure your defensive strategies match the threat when considering encryption options. Extend your defenses to include security auditing and intrusion detection. Implementing the techniques in this indispensable security resource is as close as you can get to guaranteed prevention against hackers without turning off the power switch.

Covers the latest techniques:

  • Install and configure your SQL Server environment for maximum security
  • Build and maintain a robust and protected database server
  • Protect valuable customer information, human resources data, and more
  • Defend against application software vulnerabilities and configuration issues
  • Ensure that access to data is only granted when appropriate
  • Encrypt data into an unreadable form to preserve confidentiality
  • Understand the mistakes that contributed to the spread of the SQL Slammer worm
  • Rid your applications of SQL injection bugs
  • Permit client applications to access the server securely
  • Build and utilize an effective auditing and intrusion detection plan

Product Details

  • Paperback: 352 pages
  • Publisher: McGraw-Hill Osborne Media; 1 edition (August 27, 2003)
  • Language: English
  • ISBN-10: 0072225157
  • ISBN-13: 978-0072225150
  • Product Dimensions: 9 x 7.3 x 1.1 inches
  • Shipping Weight: 1.6 pounds (View shipping rates and policies)
  • Average Customer Review: 4.8 out of 5 stars  See all reviews (4 customer reviews)
  • Amazon.com Sales Rank: #837,345 in Books (See Bestsellers in Books)

More About the Author

Chip Andrews
Discover books, learn about writers, read author blogs, and more.

Visit Amazon's Chip Andrews Page

Inside This Book (learn more)

Citations (learn more)
This book cites 3 books:
 
1 book cites this book:


Books on Related Topics (learn more)
 
 


Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product).
 
(9)
(7)
(6)

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

4 Reviews
5 star:
 (3)
4 star:
 (1)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.8 out of 5 stars (4 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
7 of 7 people found the following review helpful:
5.0 out of 5 stars Chip Andrews and crew deliver a title worthy of its lineage, October 12, 2003
"SQL Server Security" (SSS) is a great security book, free of the bloat the affects both operating systems and many technical volumes. Weighing in at 322 pages, it's packed with the detail needed to securely deploy Microsoft SQL servers. Although many people contributed to the text, it doesn't suffer from internal redundancy. I highly recommend anyone operating SQL servers devour this book.

In the "Acknowledgements," lead author Chip Andrews writes "I wanted this book to give security and database professionals the same readability, reference ability, and red-eyed wonder that 'Hacking Exposed' gave me a few years back." My favorite aspect of the HE line was the material's ability to explain attack and defense concepts while illuminating the internal operation of victimized systems. SSS follows this lead by devoting entire chapters to SQL Server components, like Network-Libraries (ch. 4) and Authentication and Authorization (ch. 5). My favorite sections appear in chapter 7, where the authors describe novel ways to leverage SQL Server's "C-2 auditing" features for purposes of intrusion detection.

SSS dispenses an immense amount of useful advice, whether it's a whole chapter on secure installation (ch. 3), best practices found in most chapters, or the appendices on stored procedures and integration with other Microsoft technologies. The only downside I found appears in chapter 2, where SQL samurai David Litchfield uses language outside the realm of most readers' understanding. For example, "the import address entry for GetProcAddress() in sqlsort.dll shifts by 12. With no SQL Server service pack, the address of the entry is at 0x42AE1010, and on SP1 and SP2, it is at 0x42AE101C" (p. 29). The uninitiated should skim this chapter and trust the authors when they claim SQL Server can be attacked by multiple means.

SSS is a must-buy if you operate SQL Server. It's the manual Microsoft forgot to ship.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
3 of 3 people found the following review helpful:
5.0 out of 5 stars Excellent coverage, December 28, 2003
By A Customer
Amazon Verified Purchase(What's this?)
Having read about half of this book, I can say that each chapter has not disappointed me. As a mid-level DBA, this book has helped bring things together in my mind that seemed like a loose collection before. I would highly recommend this book to anyone wanting to beef up their knowledge of security with SQL Server. The authors have done an excellent job. It's easy to read and chapters are reasonably short and concise with just the right amount of illustrations.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
2 of 3 people found the following review helpful:
5.0 out of 5 stars Clearly addresses SQL Server vulnerabilities, January 12, 2004
By Midwest Book Review (Oregon, WI USA) - See all my reviews
SQL Server Security by David Lichtfield clearly addresses SQL Server vulnerabilities and provides security solutions, as well as covering installation, administration, and programming, plus security issues such as authentication, encryption, intrusion detection, and more. Written for IT professionals administering or programming any SQL Server-based application, SQL Server Security includes coverage of SQL Server 7, SQL Server 2000, and SQL Server (Yukon).
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

4.0 out of 5 stars u use SQL? u better read this!
If you do anything with SQL and need top secure it, please read this book.

Securing SQL is not rocket science, but it is easy to do wrong.

This book shows how to do it right.

Published on October 31, 2003 by Eric Kent

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 

Search Customer Discussions
Search all Amazon discussions
   



So You'd Like to...


Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.